What is fwknop?
fwknop stands for "Firewall Knock Operator" and is an upcoming piece of software that will be released at the DEFCON 12 conference in July, 2004 in Las Vegas.
fwknop implements network access controls (via iptables) based on a flexible port knocking mini-language, but with a twist; it combines port knocking and passive operating system fingerprinting to make it possible to do things like only allow, say, Linux-2.4/2.6 systems to connect to your SSH daemon.
fwknop supports shared, multi-protocol port knock sequences along with both relative and absolute timeouts, and coded port knock sequences encrypted with the Rijndael block cipher.
你的防火墙可以只让操作系统是Linux内核版本2.6的主机登录吗?如果不能,这个工
具可以。
不过这个工具有点江湖的味道,感觉不是象武当少林那样的四大门派出的,有一点蓝
凤凰和桃谷六仙的感觉。
DOWN:
http://www.cipherdyne.org/fwknop/